如何禁止通过Firebase控制台修改实时数据库且保留其他Editor权限?
Absolutely, you can enforce this workflow while keeping your team’s access to other Firebase services intact. Here’s how to make it happen:
Step 1: Create a dedicated service account for your deployment pipeline
First, set up a service account exclusively for your content repository to push data to the Realtime Database. Head to your Firebase project settings → Service Accounts → Generate New Private Key. Save the JSON file securely—this is what your CI/CD tool will use to authenticate database writes. Note the service account's UID (you can find this in the JSON file underclient_email, or look it up in the IAM section of your Google Cloud Console).Step 2: Lock down Realtime Database with security rules
The core fix relies on Firebase’s security rules to restrict write access only to your dedicated service account. This way, even if team members have Editor access to the overall Firebase project, they won’t be able to modify data via the console.Example rules (adjust read permissions to match your team’s needs):
{ "rules": { // Allow read access to authenticated users (set to true if public read is acceptable) ".read": "auth != null", // Restrict writes exclusively to your deployment service account ".write": "auth != null && auth.uid === 'YOUR_SERVICE_ACCOUNT_UID'" } }Replace
YOUR_SERVICE_ACCOUNT_UIDwith the UID you noted from the service account JSON.Step 3: Validate the setup
Test by logging into the Firebase Console with a team member’s Editor account and attempting to modify a database entry—you should get a permission denied error. At the same time, your CI/CD pipeline using the service account should still push updates without issues.
Why this works
Firebase Realtime Database’s security rules operate at the data level, independent of project-wide IAM permissions. This means your team can retain Editor access to other services (like Auth, Storage, or Firestore) while being blocked from writing to the Realtime Database via the console. You can still grant read access through the same rules, so your team can view data in the console if needed.
内容的提问来源于stack exchange,提问作者James Trickey

